CVE-2026-68104
Last modified
CVE-2026-68104 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Call pm_genpd_remove() to unregister from global list prior to releasing acp_genpd memory, and clear the pointer after free. (cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2). EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd Call pm_genpd_remove() to unregister from global list prior to releasing acp_genpd memory, and clear the pointer after free. (cherry picked from commit cd8650d7a91ee8b768e202354672553faa5cc1f2)
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 25030321ba2860c56651429a4f28d94a6483d952, < 4d7c10b0bf09d90c81818752decbdb1966b62702; >= 25030321ba2860c56651429a4f28d94a6483d952, < 493adf29d66f23888f0e29888b6bc9512acd0825; >= 25030321ba2860c56651429a4f28d94a6483d952, < 2e406b86144c1f732eb344f1f1e09043856cfc33; >= 25030321ba2860c56651429a4f28d94a6483d952, < bdfc7f1e0900ef1361b828c4f69b72701f8a0a86; >= 25030321ba2860c56651429a4f28d94a6483d952, < 5c0a82283271759fff445ac27182072f200a888c; >= 25030321ba2860c56651429a4f28d94a6483d952, < 08fee493e0261f9e4120a5c8e7e42e8a723574e8; >= 25030321ba2860c56651429a4f28d94a6483d952, < 930a5dc3df4aa5e10393134bd5313d616dbebaf6; >= 25030321ba2860c56651429a4f28d94a6483d952, < 28c9b3c5dc35cc790d11e26ca3fc6e068be63998 |
| Linux | Linux | 4.6 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68104?
How severe is CVE-2026-68104?
How do I fix CVE-2026-68104?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68099In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6810The Booking Calendar Contact Form plugin for WordPress is vu…5.3
- CVE-2026-68100In the Linux kernel, the following vulnerability has been re…8.1
- CVE-2026-68101Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-68102In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68103In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-68105In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68106In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-68107In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-68108In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-68109In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6811Stack exhaustion vulnerability in the MongoDB PHP driver can…7.5
Are you affected by CVE-2026-68104?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
